Executive Summary
In late 2025, the Advanced Persistent Threat (APT) group known as ToddyCat launched a sophisticated cyber espionage campaign targeting corporate environments across Europe and Asia. The attackers leveraged a new custom tool, TCSectorCopy, to steal Microsoft Outlook emails and Microsoft 365 OAuth 2.0 access tokens. By compromising user endpoints and abusing browser-based authentication flows, ToddyCat successfully exfiltrated sensitive email data and bypassed perimeter controls. The campaign, marked by its stealthy techniques, enabled attackers to maintain persistent access and move laterally within affected networks, significantly increasing the risk to sensitive enterprise communications and intellectual property.
This incident highlights the growing reliance of threat actors on token theft and cloud-based attack vectors, posing new challenges for organizations with hybrid or cloud-first environments. It underscores the urgent need for advanced detection capabilities, Zero Trust network segmentation, and comprehensive identity protection strategies to counter emerging APT tactics.
Why This Matters Now
Token-based and email compromise attacks are escalating, exploiting hybrid and cloud authentication gaps. Today’s security programs must address lateral attacker movement and credential/token theft, given rapid cloud adoption and the sophistication of modern APTs like ToddyCat.
Attack Path Analysis
ToddyCat gained initial access through user compromise, ultimately obtaining OAuth tokens via browser session hijacking. The attackers escalated their privileges by leveraging stolen credentials to impersonate more privileged users or access sensitive applications. They moved laterally across cloud or internal networks, seeking valuable email systems and authentication stores. Establishing persistent command and control channels, the threat actors communicated with compromised workloads, blending into normal network activity. Sensitive Outlook emails and Microsoft 365 access tokens were exfiltrated using custom tools. The impact included unauthorized data exposure and the potential for further business disruption and abuse of cloud services.
Kill Chain Progression
Initial Compromise
Description
Attackers used phishing or browser-based session hijacking techniques to compromise a user's credentials and initiate access to the organization.
Related CVEs
CVE-2024-11859
CVSS 6.8A DLL search order hijacking vulnerability in ESET's command-line scanner allows attackers to execute arbitrary code by loading a malicious DLL.
Affected Products:
ESET Command Line Scanner – < 2024.1.0.0
Exploit Status:
exploited in the wildCVE-2021-36276
CVSS 7.8An insufficient access control vulnerability in Dell's DBUtilDrv2.sys driver allows attackers to gain kernel-level access.
Affected Products:
Dell DBUtilDrv2.sys Driver – < 2.5.0.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Unsecured Credentials: Credentials In Files
Email Collection: Remote Email Collection
Steal Application Access Token
Valid Accounts: Cloud Accounts
Input Capture: Keylogging
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Exploitation for Credential Access
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure Authentication for User Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – Implement and Review Information Security Policies
Control ID: Art 9(2)(b)
CISA Zero Trust Maturity Model 2.0 – Strengthen Identity and Access Controls
Control ID: Identity Pillar - Authentication
NIS2 Directive – Technical and Organisational Measures for Access Control
Control ID: Article 21(2)(a)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Critical OAuth token theft risks compromise banking systems, requiring enhanced email security, zero trust segmentation, and threat detection capabilities.
Information Technology/IT
APT targeting Microsoft 365 tokens exposes IT infrastructure vulnerabilities, demanding multicloud visibility, egress security, and inline inspection controls.
Government Administration
ToddyCat's corporate email access methods threaten sensitive government communications, necessitating encrypted traffic protection and anomaly response systems.
Health Care / Life Sciences
Email data breaches violate HIPAA compliance requirements, mandating east-west traffic security and threat detection for protected health information.
Sources
- ToddyCat’s New Hacking Tools Steal Outlook Emails and Microsoft 365 Access Tokenshttps://thehackernews.com/2025/11/toddycats-new-hacking-tools-steal.htmlVerified
- APT Group “ToddyCat” Exploits ESET Vulnerability to Silently Deploy Malwarehttps://www.thaicert.or.th/en/2025/04/09/apt-group-toddycat-exploits-eset-vulnerability-to-silently-deploy-malware/Verified
- Kaspersky uncovers new ToddyCat APT group cyber espionage toolshttps://usa.kaspersky.com/about/press-releases/kaspersky-uncovers-new-toddycat-apt-group-cyber-espionage-toolsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF controls such as Zero Trust Segmentation, egress policy enforcement, inline threat detection, and end-to-end encryption could have detected, prevented, or restricted attacker movement and exfiltration at several kill chain stages. These measures reduce lateral movement, enforce least privilege, enhance visibility, and block the exfiltration of sensitive data.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of malicious sign-in or anomalous authentication attempts.
Control: Zero Trust Segmentation
Mitigation: Enforced least-privilege boundaries, limiting the blast radius of compromised credentials.
Control: East-West Traffic Security
Mitigation: Detects and blocks unauthorized internal connections between workloads.
Control: Cloud Firewall (ACF) with Inline IPS
Mitigation: Blocks known bad command and control signatures and unexpected outbound communications.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents sensitive data from being exfiltrated via unauthorized outbound flows.
Delivers rapid visibility and alerts on breaches, limiting business and reputational damage.
Impact at a Glance
Affected Business Functions
- Email Communications
- Data Security
- IT Operations
Estimated downtime: 5 days
Estimated loss: $500,000
Unauthorized access to corporate email data, including sensitive communications and potential exposure of confidential information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation and least privilege access policies across cloud workloads and users.
- • Enforce robust egress filtering to detect and block data exfiltration and command & control outbound communications.
- • Deploy inline threat detection and anomaly response to monitor for suspicious authentication and lateral movement.
- • Encrypt all data-in-transit—including internal flows—with high-performance traffic encryption (MACsec, IPsec) to prevent interceptor-based attacks.
- • Enhance centralized multicloud visibility to accelerate detection, investigation, and response to breaches targeting SaaS and cloud resources.



